2026 CVE Vulnerabilities
68,230 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32297 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or ... |
| CVE-2026-32296 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent... |
| CVE-2026-32295 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials. |
| CVE-2026-32294 | HIGH | 7 | 0.1% | Mar 17, 2026 | JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a comp... |
| CVE-2026-32293 | MEDIUM | 6.3 | 0.3% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL... |
| CVE-2026-32292 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede... |
| CVE-2026-32291 | HIGH | 7 | 0.3% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requ... |
| CVE-2026-32290 | HIGH | 7 | 0.2% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware f... |
| CVE-2026-25770 | HIGH | 7.2 | 1.0% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ... |
| CVE-2026-25769 | CRITICAL | 9.1 | 9.2% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.1... |
| CVE-2026-25534 | CRITICAL | 9.1 | 0.2% | Mar 17, 2026 | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri... |
| CVE-2026-21570 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, ... |
| CVE-2026-4148 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu... |
| CVE-2026-4147 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is... |
| CVE-2026-28506 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for... |
| CVE-2026-24901 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (I... |
| CVE-2026-23759 | HIGH | 8.6 | 1.5% | Mar 17, 2026 | Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection ... |
| CVE-2026-21886 | HIGH | 8.1 | 0.2% | Mar 17, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2026-4318 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform... |
| CVE-2026-3564 | CRITICAL | 9 | 0.4% | Mar 17, 2026 | A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material ... |
| CVE-2026-4324 | MEDIUM | 5.4 | 0.3% | Mar 17, 2026 | A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use... |
| CVE-2026-3888 | HIGH | 7.8 | 0.4% | Mar 17, 2026 | Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private ... |
| CVE-2026-4271 | HIGH | 7.5 | 0.8% | Mar 17, 2026 | A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs... |
| CVE-2026-30911 | HIGH | 8.1 | 0.4% | Mar 17, 2026 | Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop... |
| CVE-2026-28779 | HIGH | 7.5 | 0.7% | Mar 17, 2026 | Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now